<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - sandbox-bypass</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/sandbox-bypass/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2012-10-24T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/sandbox-bypass/atom.xml</id>
    <entry xml:lang="en">
        <title>Java Exploits: Offense and Defense</title>
        <published>2012-10-24T00:00:00+00:00</published>
        <updated>2012-10-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/java-exploits/"/>
        <id>https://blog.itys.net/vol1/posts/java-exploits/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/java-exploits/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmons (ISC)2 Twin Cities Chapter presentation Java Exploits:
Offense and Defense, delivered on October 24, 2012, examines the pervasive risk
of client-side Java vulnerabilities and outlines why these flaws represent a
critical attack vector for organizations. Harmon, drawing on his two decades of
security experience, highlights how the Java sandbox can be bypassed via
reflection and code injectiondemonstrated by high-impact exploits documented by
researchers like Joshua Drake and Adam Gowdiakand underscores the urgency of
addressing these pervasive weaknesses.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;attacks&quot;&gt;Attacks&lt;&#x2F;h2&gt;
&lt;p&gt;The talk begins by quantifying the threat: in 2012 alone, 23 out of 50 Oracle
JRE vulnerabilities carried a CVSS score of 10, signaling complete system
compromise without authentication. Harmon dissects sample exploit code that
disables the Java SecurityManager by injecting an AllPermission-granted
ProtectionDomain, illustrating how easily an attacker can escalate privileges.
He reviews major sandbox escapes and stresses that patch cycles alone cannot
keep pace with adversaries who weaponize newly discovered flaws .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;defense&quot;&gt;Defense&lt;&#x2F;h2&gt;
&lt;p&gt;To counter these risks, Harmon presents a two-pronged defense strategy. On the
technical side, he advocates strict whitelisting of Java applets via Group
Policy, Click-to-Run settings in browsers to prevent drive-by code execution,
and deployment of inline or local sandboxessuch as Invinceas VM-based isolation
or FireEye appliancesto contain untrusted code. Complementing this, he urges
policy-driven measures: eliminate Java where it isnt business-critical, enforce
inventory and configuration controls per the SANS Critical Security Controls
(especially Controls 15), and integrate Java risk assessments into broader
security governance. By combining these controls, organizations can
substantially reduce their Java attack surface and stay ahead of emerging
exploit techniques .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56224_2012-10-24_JavaExploitsOffenseAndDefense-ISC2TC.pdf&quot;&gt;Java Exploits Offense and
Defense&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
